|
208651
|
7.5 |
HIGH
Network
|
apache
|
beam
|
The Apache Beam MongoDB connector in versions 2.10.0 to 2.16.0 has an option to disable SSL trust verification. However this configuration is not respected and the certificate verification disables t…
|
CWE-295
Improper Certificate Validation
|
CVE-2020-1929
|
2024-11-21 14:11 |
2020-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208652
|
4.3 |
MEDIUM
Network
|
otrs debian
|
otrs debian_linux
|
Agent A is able to save a draft (i.e. for customer reply). Then Agent B can open the draft, change the text completely and send it in the name of Agent A. For the customer it will not be visible that…
|
NVD-CWE-Other
|
CVE-2020-1767
|
2024-11-21 14:11 |
2020-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208653
|
6.1 |
MEDIUM
Network
|
otrs debian
|
otrs debian_linux
|
Due to improper handling of uploaded images it is possible in very unlikely and rare conditions to force the agents browser to execute malicious javascript from a special crafted SVG file rendered as…
|
CWE-79
Cross-site Scripting
|
CVE-2020-1766
|
2024-11-21 14:11 |
2020-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208654
|
5.3 |
MEDIUM
Network
|
otrs debian opensuse
|
otrs debian_linux leap backports_sle
|
An improper control of parameters allows the spoofing of the from fields of the following screens: AgentTicketCompose, AgentTicketForward, AgentTicketBounce and AgentTicketEmailOutbound. This issue a…
|
NVD-CWE-Other
|
CVE-2020-1765
|
2024-11-21 14:11 |
2020-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208655
|
7.5 |
HIGH
Network
|
apache
|
olingo
|
Apache Olingo versions 4.0.0 to 4.7.0 provide the AsyncRequestWrapperImpl class which reads a URL from the Location header, and then sends a GET or DELETE request to this URL. It may allow to impleme…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-1925
|
2024-11-21 14:11 |
2020-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208656
|
5.3 |
MEDIUM
Network
|
huawei
|
cloudengine_12800_firmware s5700_firmware s6700_firmware
|
There is a weak algorithm vulnerability in some Huawei products. The affected products use the RSA algorithm in the SSL key exchange algorithm which have been considered as a weak algorithm. Attacker…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2020-1810
|
2024-11-21 14:11 |
2020-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208657
|
4.6 |
MEDIUM
Physics
|
huawei
|
mate_20_pro_firmware
|
HUAWEI Mate 20 Pro smartphones versions earlier than 10.0.0.175(C00E69R3P8) have an improper authentication vulnerability. The software does not sufficiently validate the name of apk file in a specia…
|
CWE-287
Improper Authentication
|
CVE-2020-1786
|
2024-11-21 14:11 |
2020-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208658
|
4.4 |
MEDIUM
Local
|
huawei
|
honor_magic2_firmware
|
Huawei Honor Magic2 mobile phones with versions earlier than 10.0.0.175(C00E59R2P11) have an information leak vulnerability. Due to a module using weak encryption tool, an attacker with the root perm…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2020-1826
|
2024-11-21 14:11 |
2020-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208659
|
6.6 |
MEDIUM
Physics
|
huawei
|
mate_20_firmware
|
HUAWEI Mate 20 smartphones versions earlier than 9.1.0.139(C00E133R3P1) have an improper authentication vulnerability. The system has a logic error under certain scenario, successful exploit could al…
|
CWE-287
Improper Authentication
|
CVE-2020-1787
|
2024-11-21 14:11 |
2020-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208660
|
8.2 |
HIGH
Network
|
huawei
|
usg9500_firmware
|
USG9500 with software of V500R001C30SPC100; V500R001C30SPC200; V500R001C30SPC600; V500R001C60SPC500; V500R005C00SPC100; V500R005C00SPC200 have an improper credentials management vulnerability. The so…
|
NVD-CWE-noinfo
|
CVE-2020-1871
|
2024-11-21 14:11 |
2020-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|